VulnScope — 以套件為主體的 CVE 查詢工具- HIGH8.6CVE-2026-44023Docling Core: Unsafe remote filename resolution
- HIGH8.1CVE-2026-44019Docling Core: Insufficient validation of image reference URIs
- HIGH7.1Docling: Unsafe URI and Path Handling in HTML Backend
- HIGH7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
- HIGH8.2Docling: Unsafe Playwright-based HTML Rendering
- HIGH7.5EPSS 0.05%React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
- HIGH8.1EPSS 0.25%React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
- HIGH8.0EPSS 0.03%React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
- HIGH7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
- HIGH7.5AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
- HIGH8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
- HIGH8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
- HIGH8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
- HIGH8.2DOMPurify XSS via selectedcontent re-clone
- HIGH8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
- HIGH7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
- HIGH8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
- HIGH8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
- HIGH8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
- HIGH8.8PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
- HIGH8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
- HIGH8.6NodeVM network builtin exclusions bypass via internal _http_client and _http_server
- HIGH7.5EPSS 0.06%ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag
- HIGH8.6vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain